Security detection method and device
By introducing a tamper-proof unit on the microcontroller and detecting and disabling the debugging interface, ensuring that the boot loader is executed when the boot loader is valid, the risk of data tampering in flash memory is solved and data security is improved.
Patent Information
- Application Number
- CN202510222448.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-27
- Publication Date
- 2025-06-10
AI Technical Summary
In the prior art, the contents of flash memory can be repeatedly rewritten, resulting in the risk of tampering with programs and data in the microcontroller, lacking security, and unable to effectively protect data.
By introducing a tamper-proof unit on the microcontroller, disable the debugging interface after detecting a vulnerability, and execute the boot loader when the boot loader is valid, thereby avoiding the execution of the tampered boot loader and ensuring data security.
It effectively prevents the execution of the tampered boot loader, avoids data loss, and improves the security of data in the microcontroller memory while having boot loading and debugging functions.
Smart Images

Figure CN120124072A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of security detection technologies, and in particular, to a security detection method and device. Background Art
[0002] The programs and data of a microcontroller are usually stored in a non-volatile memory to ensure that the programs and data will not be lost after a power failure. Non-volatile memories include read-only memories, one-time programmable memories, and flash memories. The content stored in a read-only memory needs to be determined during the chip production stage and cannot be modified by the user subsequently; a one-time programmable memory can be written once by the user after the chip is shipped, and the content cannot be modified thereafter; the content of a flash memory can be erased and rewritten multiple times, and is more flexible to use. Therefore, flash memories are currently commonly used to store programs and data.
[0003] However, since the content of a flash memory can be erased and rewritten multiple times, there is a risk that the programs and data in the flash memory may be tampered with, making it impossible to protect the programs and data and lacking security. Therefore, how to ensure the security of data in a microcontroller still needs further research. Summary of the Invention
[0004] Embodiments of the present invention provide a security detection method and device to improve the security of data in a memory of a microcontroller.
[0005] In a first aspect, embodiments of the present invention provide a security detection method. This method is applicable to a detection device and includes: after a tamper-proof unit on the microcontroller of the detection device detects that there is a vulnerability in the microcontroller, disabling a debug interface on the microcontroller, where the debug interface is used to monitor and / or debug the operation of a bootloader stored in a first memory of the microcontroller; when it is determined that the bootloader is valid, executing the bootloader through a processor on the microcontroller.
[0006] By using the above method, after a tamper-proof unit on the microcontroller of the detection device detects that there is a vulnerability in the microcontroller, the debug interface on the microcontroller is disabled, and the bootloader is executed only when the bootloader is valid, thereby avoiding data loss caused by executing a tampered bootloader. In this way, while the detection device has the functions of bootloading and debugging, the security of data in the memory on the microcontroller is improved.
[0007] In an optional embodiment, the method further includes: when it is determined that the bootloader fails, erasing sensitive information in a third memory of the microcontroller.
[0008] Using the above method, after detecting a vulnerability in the microcontroller and the bootloader fails, it indicates that the microcontroller has been invaded at this time. Erasing the sensitive information in the third memory of the microcontroller can ensure the security of the data in the microcontroller.
[0009] In an optional embodiment, the sensitive information includes a key, and the key is used to decrypt the program file stored in the first memory to obtain the bootloader.
[0010] Using the above method, the bootloader needs to be decrypted with a key to be obtained, which further prevents the bootloader from being tampered with.
[0011] In an optional embodiment, the presence of a vulnerability in the microcontroller includes at least one of the following: content is written to the third memory of the microcontroller; the first terminal pin of the anti-tampering unit returns a first value, and the first value is used to indicate that the casing of the detection device is opened; the second terminal pin of the anti-tampering unit returns a second value, and the second value is used to indicate that a short circuit or open circuit has occurred in the wires arranged on the top of the microcontroller; it is detected that the debug interface is enabled externally through software; it is detected that the debug interface is disabled externally through software; the voltage of the external power supply of the microcontroller does not conform to a first preset voltage; the external power supply of the microcontroller stops power supply; the voltage of the backup battery of the microcontroller does not conform to a second preset voltage; the real-time clock oscillator of the microcontroller fails.
[0012] In an optional embodiment, the method further includes: verifying the bootloader using a preset verification algorithm; when the verification passes, determining that the bootloader is valid, and when the verification fails, determining that the bootloader is invalid.
[0013] In a second aspect, an embodiment of the present invention provides a security detection device, which includes a microcontroller, and the microcontroller includes: an anti-tampering unit, configured to disable the debug interface on the microcontroller after detecting a vulnerability in the microcontroller, and the debug interface is used to monitor and / or debug the operation of the bootloader stored in the first memory of the microcontroller; a processing unit, configured to execute the bootloader when determining that the bootloader is valid.
[0014] In an optional embodiment, the processing unit is further configured to erase the sensitive information in the third memory of the microcontroller when determining that the bootloader is invalid.
[0015] In an optional embodiment, the sensitive information includes a key, and the key is used to decrypt the program file stored in the first memory to obtain the bootloader.
[0016] In an alternative embodiment, the microcontroller has vulnerabilities, including at least one of the following: the third memory of the microcontroller is written; the first terminal pin of the anti-tampering unit returns a first value, which is used to indicate that the housing of the detection device is opened; the second terminal pin of the anti-tampering unit returns a second value, which is used to indicate that a short circuit or open circuit has occurred in the wires arranged on the top of the microcontroller; it is detected that the debug interface is externally enabled by software; it is detected that the debug interface is externally disabled by software; the voltage of the external power supply of the microcontroller does not conform to the first preset voltage; the external power supply of the microcontroller stops power supply; the voltage of the backup battery of the microcontroller does not conform to the second preset voltage; the real-time clock oscillator of the microcontroller fails.
[0017] In an alternative embodiment, the processing unit is further configured to verify the bootloader by using a preset verification algorithm; in the case of passing the verification, it is determined that the bootloader is valid, and in the case of failing the verification, it is determined that the bootloader is invalid.
[0018] In a third aspect, an embodiment of the present invention provides a security detection device, which includes: a memory for storing a computer program; a processor for, when executing the computer program stored on the memory, executing the method described in the first aspect above according to the obtained program.
[0019] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, in which a computer program is stored, and when a computer reads and executes the computer program, the method described in the first aspect above is executed.
[0020] In a fifth aspect, an embodiment of the present invention provides a computer program product, and when a computer reads and executes the computer program product, the method described in the first aspect above is executed. Description of the Drawings
[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for description in the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to these drawings without creative efforts.
[0022] Figure 1 It is a schematic structural diagram of a microcontroller in a detection device;
[0023] Figure 2 It is a schematic system architecture diagram of a security detection provided by an embodiment of the present application;
[0024] Figure 3 Schematic diagram of the structure of the microcontroller of a detection device applicable to security detection provided by an embodiment of the present application;
[0025] Figure 4 Flowchart corresponding to a security detection method provided by an embodiment of the present application;
[0026] Figure 5 Flowchart corresponding to a security detection method provided by an embodiment of the present application;
[0027] Figure 6 Schematic diagram of the structure of a security detection device provided by an embodiment of the present application;
[0028] Figure 7 Schematic diagram of the structure of a device of a security detection equipment provided by an embodiment of the present application. Detailed implementation manners
[0029] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention. In the embodiments of the present invention, "a plurality of" means two or more. Terms such as "first" and "second" are only used for the purpose of distinguishing descriptions, and cannot be understood as indicating or implying relative importance, nor can they be understood as indicating or implying an order.
[0030] Figure 1 Schematic diagram of the structure of the microcontroller 101 in the detection device. As Figure 1 shown, the microcontroller 101 includes a processor 102, a flash memory 104, a read-only memory 103, a serial port 105, and a debug interface 106. When the detection device is powered on or reset, the processor 102 executes the boot_rom program in the read-only memory 103, and the boot_rom program is used to detect and determine the memory specifically storing the boot loader, that is, the boot loader is stored in Figure 1In the flash memory 104. Among them, the boot_rom program in the read-only memory 103 is written during the chip production process and cannot be modified. If the processor 102 detects that the terminal pin corresponding to the bootloader returns the default value, the processor 102 executes the bootloader in the flash memory, so that the application program is loaded into the flash memory 104. The application program is received by the serial port 105 or the debug interface 106 of the processor 102 and written into the flash memory; if the processor detects that the terminal pin corresponding to the bootloader returns a non-default value, the processor does not execute the bootloader.
[0031] Introducing the mechanism of the bootloader in the flash memory of the microcontroller can bring convenience to the subsequent update and debugging of the application program. However, since the content of the flash memory can be erased and written repeatedly, this also leads to the possibility that the bootloader stored in the flash memory may be maliciously exploited by intruders. By tampering with the value of the terminal pin corresponding to the bootloader, the controller is placed in the bootloader mode, and the bootloader is tampered with through the debug interface 106, and the tampered bootloader is executed to load the malicious program into the flash memory. When the detection device is reset, the processor will execute the malicious program, which causes the processor to read the data in the memory and transmit the data in an illegal way. If Figure 1 the microcontroller without the bootloader function and the debug interface, the flexibility of the detection device will be reduced, and it is not easy to program and debug the application program in the microcontroller.
[0032] Based on this, the embodiment of the present invention provides a security detection method. After the anti-tampering unit on the microcontroller of the detection device detects a vulnerability during the power-on startup process of the microcontroller, it disables the debug interface on the microcontroller and terminates the startup. Only when the bootloader is valid, the bootloader is executed, so as to avoid data loss caused by executing the tampered bootloader. In this way, while the detection device has the functions of bootloading and debugging, the security of the data in the internal memory of the microcontroller is improved.
[0033] The method provided by the embodiment of the present application will be described in detail below with specific embodiments.
[0034] Figure 2 It is a schematic diagram of the system architecture of a security detection provided by an embodiment of the present application, as Figure 2As shown, the system at least includes a detection device 201 and a device to be detected 202. The device to be detected 202 encrypts data information and sends it to the detection device 201. The detection device 201 decrypts the received data information using a corresponding key for the application program on the microcontroller of the detection device 201's detection device, performs operations on the decrypted data information in a Double Data Rate (DDR) dynamic memory, and stores the data information after the operations in a third memory. Among them, the data information stored in the third memory is sensitive information and its security needs to be ensured. The vulnerability detection of the microcontroller can be performed through the anti-tampering unit on the microcontroller. When it is detected that there are vulnerabilities in the microcontroller during the power-on startup process, that is, there is a risk that the detection device is invaded. At this time, the debug interface on the microcontroller is disabled and the startup is terminated. Only when it is determined that the bootloader is valid, the bootloader is executed. In this way, it can effectively prevent intruders from tampering with the bootloader through the debug interface, and then loading malicious programs into the microcontroller to illegally obtain sensitive information in the microcontroller. It should be noted that the embodiments of the present application do not impose any restrictions on the number of devices to be detected involved in the above system framework. For example, there can be more devices to be detected, or fewer devices to be detected, or other devices are also included. Figure 2 Only one detection device and three devices to be detected are taken as examples for description. It should be noted that the bootloader in the embodiments of the present application is secure, that is, the bootloader has not been tampered with, indicating that the bootloader is valid. When the bootloader is tampered with, it means that the bootloader is insecure at this time, that is, the bootloader is invalid.
[0035] Based on the above system architecture, the embodiments of the present application also provide a structural schematic diagram of a microcontroller of a detection device suitable for security detection, as Figure 3 shown, the microcontroller 301 includes: a processor 302, an anti-tampering unit 303, an encryption and decryption module 304, a first memory 305, a second memory 306, a third memory 307, a DDR 308, a debug interface 309, a serial port 310, a backup battery 311, a real-time clock oscillator 312, a bus 313, an external power supply 314, a first terminal pin 315, and a second terminal pin 316.
[0036] Among them, the anti-tampering unit 303 is used to detect whether there are vulnerabilities during the power-on startup process of the microcontroller. The encryption and decryption module 304 includes an encryption algorithm and a decryption algorithm, which are used to decrypt the program file stored in the first memory using the corresponding key to obtain the bootloader, and are also used to decrypt the received data information, and are also used to encrypt the data information using the encryption algorithm before output. The first memory 305 is used to store the program file and the decrypted bootloader. The second memory 306 is used to store the application program. The application program received through the first interface of the microcontroller is written into the second memory of the microcontroller, and the application program is executed by the bootloader of the processor 302. Among them, the first interface can be a serial port 310, such as UART, or a debug interface 309, such as JTAG, which is not limited here. The serial port 310 is used to receive the application program. The debug interface 309 is used to monitor and / or debug the operation of the bootloader stored in the first memory of the microcontroller and / or receive the application program. The third memory 307 is used to store sensitive information, including keys and data information. The application program on the microcontroller decrypts the received data information using the corresponding key, performs operations on the decrypted data information in the DDR, and stores the calculated data information in the third memory. The external power supply 314 supplies power to all modules on the microcontroller. In the normal mode, the microcontroller does not use the backup battery 311 for power supply. Only when the external power supply is interrupted, it switches to the backup battery for power supply to ensure that the modules on the microcontroller can continue to work. The first terminal pin 315 and the second terminal pin 316 are two terminal pins provided on the anti-tampering unit 303. A pull-down resistor is coupled to the first terminal pin 315 and extends to the external mechanical switch of the detection device. The switch remains pressed (closed), so that the power supply voltage is transmitted to the first terminal pin through the pressed switch. If the intruder opens the casing of the detection device, the external switch will open, thereby disconnecting the connection between the power supply voltage and the tamper control terminal of the microcontroller package, and the first terminal pin returns the first value. If the casing of the detection device is not opened, that is, the external switch of the detection device is in the closed state, the first sub-pin returns a non-first value; the second terminal pin 316 is connected to the wires arranged on the top of the detection device. Multiple pairs of wires form a grid and are arranged on the top of the detection device. Each pair of wires extends parallel through the top of the microcontroller in a serpentine manner. The first wire of each pair of wires is connected to the second terminal pin, and the second wire is coupled to the second terminal pin with the first wire. If any wire is broken (i.e., open circuit), or the two wires touch each other (i.e., short circuit), the second terminal pin returns the second value. Therefore, when the intruder attempts to pass a probe through the grid, there may be a situation where the wire is broken or the two wires touch each other. At this time, the return value of the second terminal pin can be used to determine whether there are vulnerabilities in the microcontroller.
[0037] Figure 4 The figure is a flowchart corresponding to a security detection method provided by an embodiment of this application. This method can be executed by a device of a detection device (abbreviated as the detection device). As Figure 4 shown, this method includes the following steps:
[0038] Step 401, after detecting a vulnerability in the microcontroller through the anti-tampering unit on the microcontroller of the detection device, disable the debug interface on the microcontroller.
[0039] Specifically, the detection device detects the microcontroller through the anti-tampering unit on the microcontroller of the detection device to check whether the microcontroller has vulnerabilities (i.e., the risk of being invaded). When the detection device detects a vulnerability in the microcontroller, it disables the debug interface on the microcontroller. The debug interface is used to monitor and / or debug the operation of the bootloader stored in the first memory of the microcontroller. When a vulnerability is detected during the power-on startup process of the microcontroller, the debug interface is disabled and the startup is terminated, which can effectively prevent intruders from tampering with the bootloader and ensure the security of the microcontroller. When the detection device detects that the microcontroller has no vulnerabilities, it enables the processor. The processor on the microcontroller executes the bootloader in the first memory, so that the application program received by the serial port or debug interface of the microcontroller is written into the second memory of the microcontroller, and enters the normal program operation mode. Among them, the serial port can be UART, the debug interface can be JTAG, and the bootloader is obtained by decrypting the program file stored in the first memory by the encryption and decryption module in the microcontroller using the corresponding key.
[0040] Optionally, the detection device detecting a vulnerability in the microcontroller includes at least one of the following:
[0041] (1) Content is written into the third memory of the microcontroller;
[0042] (2) The first terminal pin of the anti-tampering unit returns a first value, and the first value is used to indicate that the housing of the detection device is opened. If the first terminal pin returns the first value, it means that the housing of the detection device is opened and there is a risk of intrusion;
[0043] (3) The second terminal pin of the anti-tampering unit returns a second value, and the second value is used to indicate that a short circuit or open circuit has occurred in the wires arranged on the top of the microcontroller. If the second terminal pin returns the second value, it means that an intruder may cause a short circuit or open circuit in the wires when passing through the wires with a probe, and there is a risk of intrusion;
[0044] (4) It is detected that the debug interface is enabled externally through software;
[0045] (5) It is detected that the debug interface is disabled externally through software;
[0046] (6) The voltage of the external power supply of the microcontroller does not conform to the first preset voltage, that is, the voltage of the external power supply is not within the normal voltage range;
[0047] (7) The external power supply of the microcontroller stops supplying power;
[0048] (8) The voltage of the backup battery of the microcontroller does not conform to the second preset voltage, that is, the voltage of the backup battery is not within the normal voltage range;
[0049] (9) The real-time clock oscillator of the microcontroller fails.
[0050] Step 402, when it is determined that the bootloader is valid, execute the bootloader through the processor on the microcontroller.
[0051] Specifically, when the detection device determines that the bootloader is valid, it enables the processor on the microcontroller, executes the bootloader through the processor on the microcontroller, and enters the normal program operation mode. During this process, the debug interface is still in the disabled state.
[0052] Optionally, when the detection device determines that the bootloader fails, it erases the sensitive information in the third memory of the microcontroller. During the erasing process, it is necessary to verify whether the sensitive information in the third memory has been completely erased. After all the sensitive information in the third memory has been erased, wait for the processor to restart. Among them, the sensitive information includes keys and processed data information. The key is used to decrypt the program file stored in the first memory to obtain the bootloader. The application program on the microcontroller uses the corresponding key to decrypt the received data information, performs operations on the decrypted data information in the DDR, and stores the processed data information in the third memory.
[0053] Optionally, to determine whether the bootloader is valid, the bootloader can be verified through a preset verification algorithm. If the verification passes, it is determined that the bootloader is valid. If the verification fails, it is determined that the bootloader fails. Among them, the preset verification algorithm can be stored in the encryption and decryption module.
[0054] Using the above method, as Figure 5 shown, after the anti-tampering unit on the microcontroller of the detection device detects that the microcontroller has a vulnerability, it disables the debug interface on the microcontroller. When the bootloader is valid, it executes the bootloader, thereby avoiding data loss caused by executing the tampered bootloader. When the bootloader is invalid, it erases the sensitive information in the third memory. In addition, the debug interface can only be used when the microcontroller has no vulnerabilities. In this way, while the detection device has the functions of bootloading and debugging, it improves the security of the data in the memory of the microcontroller.
[0055] Based on the same technical concept, an embodiment of the present application provides a security detection device 6000. Figure 6 It is a schematic structural diagram of the security detection device provided by the embodiment of the present application. As Figure 6 shown, the device includes: a tamper-proof unit 601, configured to disable the debug interface on the microcontroller after detecting a vulnerability in the microcontroller, where the debug interface is used to monitor and / or debug the operation of the bootloader stored in the first memory of the microcontroller.
[0056] A processing unit 602, configured to execute the bootloader when it is determined that the bootloader is valid.
[0057] In an optional embodiment, the processing unit 602 is further configured to erase sensitive information in the third memory of the microcontroller when it is determined that the bootloader fails.
[0058] In an optional embodiment, the sensitive information includes a key, and the key is used to decrypt the program file stored in the first memory to obtain the bootloader.
[0059] In an optional embodiment, the microcontroller has a vulnerability, including at least one of the following: content is written to the third memory of the microcontroller; the first terminal pin of the tamper-proof unit returns a first value, and the first value is used to indicate that the housing of the detection device is opened; the second terminal pin of the tamper-proof unit returns a second value, and the second value is used to indicate that a short circuit or open circuit occurs in the wires arranged on the top of the microcontroller; it is detected that the debug interface is enabled externally through software; it is detected that the debug interface is disabled externally through software; the voltage of the external power supply of the microcontroller does not conform to a first preset voltage; the external power supply of the microcontroller stops power supply; the voltage of the backup battery of the microcontroller does not conform to a second preset voltage; the real-time clock oscillator of the microcontroller fails.
[0060] In an optional embodiment, the processing unit 602 is further configured to verify the bootloader by using a preset verification algorithm; when the verification passes, it is determined that the bootloader is valid, and when the verification fails, it is determined that the bootloader fails.
[0061] Based on the same technical concept, Figure 7 It is a schematic structural diagram of a device 7000 provided by the embodiment of the present application, and the device is used to implement the functions of the detection device in the above embodiment. As Figure 7As shown, the device 7000 includes at least one processor 701 and a memory 702 connected to the at least one processor 701. In the embodiments of the present application, the specific connection medium between the processor 701 and the memory 702 is not limited. Figure 7 Take the case where the processor 701 and the memory 702 are connected by a bus. The bus can be divided into an address bus, a data bus, a control bus, etc. In the embodiments of the present invention, the memory 702 stores instructions executable by the at least one processor 701. By executing the instructions stored in the memory 702, the at least one processor 701 can implement the steps of the above-mentioned security detection method.
[0062] Among them, the processor 701 is the control center of the computer device. It can use various interfaces and lines to connect various parts of the computer device. By running or executing the instructions stored in the memory 702 and calling the data stored in the memory 702, resource settings can be performed. Optionally, the processor 701 may include one or more processing units. The processor 701 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, application programs, etc., and the modem processor mainly processes wireless communication. It can be understood that the above-mentioned modem processor may not be integrated into the processor 701. In some embodiments, the processor 701 and the memory 702 can be implemented on the same chip. In some embodiments, they can also be separately implemented on independent chips.
[0063] The processor 701 can be a general-purpose processor, such as a central processing unit (CPU), a digital signal processor, an application specific integrated circuit (ASIC), a field programmable gate array, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application can be directly implemented by a hardware processor or completed by a combination of hardware and software modules in the processor.
[0064] The memory 702 serves as a non-volatile computer-readable storage medium and can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. The memory 702 may include at least one type of storage medium. For example, it may include flash memory, hard disks, multimedia cards, card-type memories, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic memories, magnetic disks, optical disks, and so on. The memory 702 is any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited to this. The memory 702 in the embodiments of the present application may also be a circuit or any other device capable of implementing a storage function, for storing program instructions and / or data.
[0065] Based on the same technical concept, an embodiment of the present invention provides a computer-readable storage medium, in which a computer program is stored, and the computer program is executed by a processor to perform the above-mentioned security detection method.
[0066] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.
[0067] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to generate a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices generate for implementing in the process Figure 1 a process or multiple processes and / or blocks Figure 1means for the functions specified in one or more boxes.
[0068] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instruction means that implement the functions specified in one Figure 1 or more processes and / or boxes Figure 1 means for the functions specified in one or more boxes.
[0069] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, so that the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one Figure 1 or more processes and / or boxes Figure 1 means for the functions specified in one or more boxes.
[0070] Obviously, those skilled in the art can make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalent technologies, this application is also intended to include these changes and modifications.
Claims
1. A safety detection method, characterized in that: The method is applicable to a detection device, and the method comprises: After detecting a vulnerability in the microcontroller through an anti-tampering unit on the microcontroller of the detection device, disabling a debugging interface on the microcontroller, wherein the debugging interface is used to monitor and / or debug the operation of a boot loader stored in a first memory of the microcontroller; When it is determined that the boot loader is valid, the boot loader is executed by a processor on the microcontroller.
2. The method according to claim 1, characterized in that The method further comprises: When it is determined that the boot loader fails, sensitive information in the third memory of the microcontroller is erased.
3. The method according to claim 2, characterized in that The sensitive information includes a key, and the key is used to decrypt the program file stored in the first memory to obtain the boot loader.
4. The method according to any one of claims 1 to 3, characterized in that The microcontroller has vulnerabilities, including at least one of the following: Content is written into the third memory of the microcontroller; The first terminal pin of the anti-tampering unit returns a first value, and the first value is used to indicate that the housing of the detection device is opened; The second terminal pin of the anti-tamper unit returns a second value, and the second value is used to indicate that a short circuit or a break circuit occurs in the wire arranged on the top of the microcontroller; It is detected that the debugging interface is enabled externally through software; Detecting that the debugging interface is disabled externally through software; The voltage of the external power supply of the microcontroller does not meet the first preset voltage; The external power supply of the microcontroller stops supplying power; The voltage of the backup battery of the microcontroller does not meet the second preset voltage; The microcontroller's real-time clock oscillator is faulty.
5. The method according to claim 1, characterized in that The method further comprises: Verifying the boot loader using a preset verification algorithm; If the verification passes, it is determined that the boot loader is valid, and if the verification fails, it is determined that the boot loader is invalid.
6. A safety detection device, characterized in that: The device comprises a microcontroller, the microcontroller comprising: an anti-tampering unit, configured to disable a debug interface on the microcontroller after detecting a vulnerability in the microcontroller, the debug interface being used to monitor and / or debug the operation of a boot loader stored in a first memory of the microcontroller; The processing unit is configured to execute the boot loader program if it is determined that the boot loader program is valid.
7. The device according to claim 6, characterized in that The device also includes: The processing unit is used to erase sensitive information in the third memory of the microcontroller when determining that the boot loader fails.
8. A safety detection device, characterized in that: The device comprises: A memory for storing program instructions; A processor is used to call the program instructions stored in the memory, and execute the steps included in any one of the methods of claims 1-5 according to the obtained program instructions.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program includes program instructions. When the program instructions are executed by a computer, the method according to any one of claims 1 to 5 is executed.
10. A computer program product, characterized in that The computer program product comprises a computer program code, which causes any one of claims 1 to 5 to be performed when the computer program code is run on a computer.